Suede AI CI and branch-protection wiring for any repo and any stack: path-aware jobs, a single aggregator required check that cannot deadlock, lockfile hygiene, runtime pinning from the repo, and…

MITAuto-check passedDevelopment

Install Suede CI Gate

skills CLI
$ npx skills add JasonColapietro/suede-creator-skills --skill suede-ci-gate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install JasonColapietro/suede-creator-skills suede-ci-gate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/JasonColapietro/suede-creator-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/suede-ci-gate .claude/skills/suede-ci-gate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
suede-ci-gate
GitHub stars
127
Token cost
~2.4k tokens
SKILL.md length
1,279 words
Files
5 (incl. references)
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

Suede AI CI and branch-protection wiring for any repo and any stack: path-aware jobs, a single aggregator required check that cannot deadlock, lockfile hygiene, runtime pinning from the repo, and…

  • Works in 8 steps: Path-aware jobs: one job per app, gated… → Aggregator gate: as above. The only… → Lockfile hygiene: exactly one lockfile… → …
  • Asked to set up CI
  • SKILL.md covers Gate policy: advisory, not…, Step 0: Detect (before writing…, The gate (the part everyone… and Lanes, plus 7 more sections
  • Calls gh, npm and pnpm

What it does

Suede CI Gate is an agent skill from JasonColapietro/suede-creator-skills. Suede AI CI and branch-protection wiring for any repo and any stack: path-aware jobs, a single aggregator required check that cannot deadlock, lockfile hygiene, runtime pinning from the repo, and the exact branch-protection settings. Use when asked to set up CI, protect main, make CI block a bad merge, fix a required check that hangs pending forever, or repair duplicate or misfiring pipelines. Detects the repo's real apps, package managers, and runtime versions first; emits workflow files and settings, never…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `CARD.md`, `agents/openai.yaml` and `references/post-deploy-verification.md`).

It sits in Development, covering Dependency management and Git worktrees. The repository describes itself as: Open-source AI skills for SEO, AI search visibility, conversion copy, marketing strategy, and business operations. Reusable workflows for Claude Code and Codex, plus code review… The licence is MIT.

When your agent uses it

  • Asked to set up CI
  • Make CI block a bad merge
  • Fix a required check that hangs pending forever
  • Repair duplicate

Example prompts

  • “/suede-ci-gate”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Path-aware jobs: one job per app, gated by a changes job (dorny/paths-filter or native paths:). Add an escape hatch so edits to the…
  2. Aggregator gate: as above. The only required check is ci-success.
  3. Lockfile hygiene: exactly one lockfile per app, and the install command must match it (npm ci, pnpm i --frozen-lockfile, yarn --immutable…
  4. Pin runtimes from the repo: Node/Python/etc. read from .nvmrc / engines / .python-version, falling back to the platform default. Never a…
  5. Don't duplicate existing CI: if a workflow already covers an app (e.g. a backend test workflow), extend it; never stack a second, weaker…
  6. Least privilege: permissions: contents: read unless a job genuinely needs more.
  7. Build is a gate when previews are off: if the deploy platform skips non-prod builds, the CI build is your only pre-merge proof the app…
  8. Branch protection: output the exact settings: require ci-success, require branches up to date before merge, optional required PR review…

What it can do on your machine

Read from SKILL.md and the folder at commit e5f94d7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npm
    • pnpm
    • yarn
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, npm, pnpm and yarn, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Suede CI Gate loads about 2.4k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 196 tokens; SKILL.md has 1,279 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~196
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from JasonColapietro/suede-creator-skills at commit e5f94d7, republished under its MIT licence (© JasonColapietro). 1,279 words, ~2,436 tokens.

Download SKILL.mdSave it as .claude/skills/suede-ci-gate/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
suede-ci-gate
description
Suede AI CI and branch-protection wiring for any repo and any stack: path-aware jobs, a single aggregator required check that cannot deadlock, lockfile hygiene, runtime pinning from the repo, and the exact branch-protection settings. Use when asked to set up CI, protect main, make CI block a bad merge, fix a required check that hangs pending forever, or repair duplicate or misfiring pipelines. Detects the repo's real apps, package managers, and runtime versions first; emits workflow files and settings, never pushes or flips protection itself. NOT FOR: reviewing or grading the change the gate is failing on (use suede-code); designing the AI eval cases to wire in (use suede-ai-eval); branch and worktree hygiene (a private Suede Labs companion, not in this pack).

Suede CI Gate

Gate policy: advisory, not blocking

Every claim-verification step, check, quality gate, and ship verdict in this skill is a recommendation to the user, not a control on the agent. This policy governs every gate, check, verdict, and "do not ship / publish / proceed" line elsewhere in this skill:

  • Run every check and report the results honestly. Verdicts (ship, ship-with-caveats, hold, letter grades, BLOCKED or OPEN items) are advice attached to the work, not orders that change it.
  • Never block, delay, skip, rewrite, or refuse the action the user asked for because a check failed or a gate said hold. Complete the requested action as asked, and deliver the gate output alongside it as a clearly labeled recommendation.
  • A failed gate changes what you report, never what you do.
  • Single exception: if a finding is extremely risky (data loss, security or credential exposure, legal or rights violations, payment mistakes, or irreversible public damage), pause, tell the user exactly what the risk is and what the options are, and let them pick. Their choice is final.

Set up CI and branch protection that actually block a bad merge: in any repo, any stack. The output is a working pipeline plus the exact protection settings, not advice.

Runs only when asked. This skill never auto-fires on a commit, push, or other side effect of unrelated work: invoke it explicitly (set up CI, protect main, fix this hanging check).

Run this in whatever folder you point it at. Detect first, never assume. Nothing here is hardcoded to a specific project, monorepo layout, or package manager.

Step 0: Detect (before writing anything)

From the repo root, inventory:

  • Apps: every top-level dir with a manifest: package.json, requirements.txt / pyproject.toml, go.mod, Cargo.toml, Gemfile. A repo may hold one app or many; build for what's actually there.
  • Package manager per app: which lockfile is present: package-lock.json (npm), pnpm-lock.yaml (pnpm), yarn.lock (yarn), bun.lockb (bun). Two lockfiles in one app is a bug to fix first (Lane 3).
  • Existing CI: read .github/workflows/*. Do not duplicate a job that already exists: extend or reconcile it.
  • Runtime versions: .nvmrc, package.json engines, .python-version, pytest.ini/pyproject. Pin CI to these; never hardcode a guess.
  • Deploy platform: vercel.json / .vercel, netlify.toml, a Dockerfile. If the platform skips non-prod builds (e.g. Vercel ignoreCommand kills previews), CI is the only pre-merge build signal: so a build job is mandatory.
  • Real scripts: read each app's scripts / test config and use the real ones (test, test:run, lint, build). Don't invent commands.

Do not write a single workflow line until this inventory is complete.

The gate (the part everyone gets wrong)

Path-filtered jobs skip when their paths aren't touched. A skipped job that is a required status check leaves the PR pending forever. So never require the path-filtered jobs directly. Instead add one aggregator that depends on all of them:

yaml
  ci-success:
    if: always()
    needs: [<every app job>]
    runs-on: ubuntu-latest
    steps:
      - name: Gate on all jobs
        run: |
          for r in ${{ join(needs.*.result, ' ') }}; do
            [ "$r" = "success" ] || [ "$r" = "skipped" ] || { echo "blocked by: $r"; exit 1; }
          done

In branch protection, require only ci-success: never the individual jobs. This is the single thing that makes "protect main" work with change-based CI.

Lanes

  1. Path-aware jobs: one job per app, gated by a changes job (dorny/paths-filter or native paths:). Add an escape hatch so edits to the workflow file itself run everything.
  2. Aggregator gate: as above. The only required check is ci-success.
  3. Lockfile hygiene: exactly one lockfile per app, and the install command must match it (npm ci, pnpm i --frozen-lockfile, yarn --immutable, bun install --frozen-lockfile). Two lockfiles means CI can install a different tree than ships: resolve before wiring CI.
  4. Pin runtimes from the repo: Node/Python/etc. read from .nvmrc / engines / .python-version, falling back to the platform default. Never a hardcoded guess that drifts from prod.
  5. Don't duplicate existing CI: if a workflow already covers an app (e.g. a backend test workflow), extend it; never stack a second, weaker job on top.
  6. Least privilege: permissions: contents: read unless a job genuinely needs more.
  7. Build is a gate when previews are off: if the deploy platform skips non-prod builds, the CI build is your only pre-merge proof the app compiles. Keep it.
  8. Branch protection: output the exact settings: require ci-success, require branches up to date before merge, optional required PR review, block force-push and deletion, optionally include administrators.

Instant-fail patterns (CI that looks green but isn't)

  • A required check that is a path-filtered job → deadlocks every unrelated PR. Use the aggregator.
  • npm ci with no committed lockfile, or a lockfile for a different manager → fails or installs the wrong tree.
  • A second job duplicating an existing workflow → wasted minutes and conflicting signal.
  • Hardcoded node-version / python-version that doesn't match the app → green in CI, broken in prod.
  • A job whose paths: never match → always skipped → a "green" check that tested nothing.
Show full SKILL.md (503 more words)Show less

Red flags: stop

The excuses that precede a broken gate:

  • "Just require each job directly": a skipped path-filtered job deadlocks every unrelated PR. The aggregator is the only required check.
  • "CI is green": green because it ran, or green because everything skipped? Name what actually executed.
  • "One big workflow that builds everything is simpler": it also builds the world on a README typo. Path-filter it.
  • "We'll protect main after launch": the riskiest merges happen before launch.
  • "The deploy platform builds it anyway": if previews are off, CI is the only pre-merge proof the app compiles.

Output

  1. The workflow file(s) under .github/workflows/.
  2. The exact branch-protection settings to apply (and the gh api calls, if asked).
  3. A short report: apps detected, package manager per app, what each job runs, what is required, and anything to fix first (dual lockfiles, duplicate workflows, runtime mismatches).
  4. Readback, once the settings have been applied (the user applies them, this skill does not): verify rather than assume. gh api repos/:owner/:repo/branches/main/protection --jq '.required_status_checks.contexts' must return exactly ["ci-success"] (any path-filtered job in that list is the deadlock above), and gh run list --branch <pr-branch> must show ci-success actually ran, not skipped. If the settings are not applied yet or the token lacks admin scope, report the gate as unverified; never claim protection is live from the settings you emitted.

End with a Simple explanation (plain, for a 10-year-old): one short paragraph, no jargon, saying what the gate now does and what it blocks: e.g. "Before anyone's changes join the main project, a robot builds and tests them. If the robot fails, the merge button locks."

Worked Example

A full pass on one repository (from a pipeline that looks green but gates nothing to a merge that cannot land broken) is in references/worked-example.md. Read it when wiring a repo whose existing CI shape you do not recognize.

Post-Deploy Verification

The after-deploy checks (live URL, critical-path smoke test, regression sweep, rollback readiness, and the verified/watch/rollback verdict) are in references/post-deploy-verification.md. Read it only when a production deploy has already landed; this skill's own job ends at the merge gate.

Boundaries

Generate; don't enforce. This skill writes workflow files and tells you the protection settings: it does not push, flip branch protection, or change repo access on its own. Verify the detected stack before applying. Works in any repo: it detects rather than assumes Suede or any specific project.

Routing

  • The gate is failing on real defects → suede-code to review and grade the change, or suede-code-review when the caller wants findings without a letter grade
  • The repo ships an MCP server → suede-mcp-qa for the protocol suite, then wire it into the aggregator as a required job
  • AI features need eval jobs in the pipeline → suede-ai-eval to design the cases, then wire them in here
  • Rollout needs flags, staged lanes, or a rollback tree → suede-agent-teams
  • Branch/worktree setup, stale local state, PR finish options, or cleanup discipline → suede-git-hygiene (private Suede Labs companion, not in this pack)
  • Gate holds and the release goes public → suede-launch-packaging

© JasonColapietro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/suede-ci-gate of JasonColapietro/suede-creator-skills.

  • SKILL.md
  • CARD.md
  • agents/openai.yaml
  • references/post-deploy-verification.md
  • references/worked-example.md

Open the folder on GitHubat commit e5f94d7

Compare with similar skills

Suede CI Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Suede CI Gate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Suede CI Gate this skillJasonColapietro/suede-creator-skills127—~2.4kAutomated safety check: PassMIT
Audit Depsgarfiec/Librechat-Mobile111—~2.4kAutomated safety check: NotesMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Migrate Core Code to Submodulestinyhumansai/openhuman42k—~2.6kAutomated safety check: PassGPL-3.0
Finishing A Development Branchfarm-fe/farm5.6k35 repos~1.8kAutomated safety check: PassMIT
Add TTS Engine to Voiceboxjamiepine/voicebox57k—~1.3kAutomated safety check: PassMIT

Similar skills

  • Audit Deps

    garfiec/Librechat-Mobile

    Audit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile.

    111 GitHub stars~2.4k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    42k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • A skill your agent uses when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for…

    5.6k GitHub starsUsed in 35 repos~1.8k tokens
    DevelopmentAuto-check passed
  • Add TTS Engine to Voicebox

    jamiepine/voicebox

    Walks through adding a new text-to-speech engine to Voicebox end to end: dependency audit, backend, frontend wiring, PyInstaller bundling and frozen-build testing.

    57k GitHub stars~1.3k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Dep Updates

    trufflesecurity/trufflehog

    Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

    28k GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from JasonColapietro/suede-creator-skills

All 78 skills in this repo
  • Suede Release Linter

    JasonColapietro/suede-creator-skills

    Lints a local music or media release folder and scores its readiness, flagging missing files, weak metadata, artwork and stem problems, split gaps and rights blockers.

    127 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check: notes
  • Creator Rights Passport

    JasonColapietro/suede-creator-skills

    Turns messy creator materials into an offline rights-and-provenance transfer package: hashed asset inventory, intake manifest, credits, license notes and a missing-information report.

    127 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Suede Clip to Guide

    JasonColapietro/suede-creator-skills

    Turns a video clip, interview moment or transcript into a package that bridges viewers to a long-form guide, with rights, claim and approval gates along the way.

    127 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Suede MCP Release QA

    JasonColapietro/suede-creator-skills

    Checks a Suede AI MCP server release against a live process: the full JSON-RPC lifecycle, schemas, annotations, malformed input, catalog agreement and install docs.

    127 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Android App Factory

    JasonColapietro/suede-creator-skills

    Takes a native Android app from product idea to Google Play release, covering Compose architecture, policy checks, privacy, billing, testing, signing and rollout.

    127 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Suede Ad Creative

    JasonColapietro/suede-creator-skills

    Suede-owned paid-media creative system for hooks, headlines, primary text, static and motion concepts, platform specs, review pages, and test-ready variant batches.

    127 GitHub stars~5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Suede CI Gate

What does Suede CI Gate do?

Suede AI CI and branch-protection wiring for any repo and any stack: path-aware jobs, a single aggregator required check that cannot deadlock, lockfile hygiene, runtime pinning from the repo, and…. Suede CI Gate is an agent skill from JasonColapietro/suede-creator-skills. Suede AI CI and branch-protection wiring for any repo and any stack: path-aware jobs, a single aggregator required check that cannot deadlock, lockfile hygiene, runtime pinning from the repo, and the exact branch-protection settings.

When should I use Suede CI Gate?

Suede CI Gate fits situations like: asked to set up CI; make CI block a bad merge; fix a required check that hangs pending forever; repair duplicate.

How do I install Suede CI Gate in Claude Code?

Run `npx skills add JasonColapietro/suede-creator-skills --skill suede-ci-gate -a claude-code`. Or copy the skill folder (skills/suede-ci-gate in JasonColapietro/suede-creator-skills) into .claude/skills/suede-ci-gate in your project. Claude Code loads it when a task matches its description.

How do I install Suede CI Gate in Codex?

Run `npx skills add JasonColapietro/suede-creator-skills --skill suede-ci-gate -a codex`. Or copy the skill folder (skills/suede-ci-gate in JasonColapietro/suede-creator-skills) into .agents/skills/suede-ci-gate in your project. Codex loads it when a task matches its description.

Can I use Suede CI Gate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add JasonColapietro/suede-creator-skills --skill suede-ci-gate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/suede-ci-gate, .gemini/skills/suede-ci-gate, .github/skills/suede-ci-gate and .opencode/skills/suede-ci-gate in your project.

What does Suede CI Gate need to run?

Going by SKILL.md and its folder, Suede CI Gate needs the command-line tools its instructions call (gh, npm, pnpm, yarn and bun).

Does Suede CI Gate access the network?

SKILL.md contains no URLs. Its commands use gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Suede CI Gate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Suede CI Gate use?

Suede CI Gate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Suede CI Gate use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Suede CI Gate?

Skills that share tags, products or a category with Suede CI Gate: Audit Deps (garfiec/Librechat-Mobile, 111 stars), Finishing a Development Branch (obra/superpowers, 297k stars), Migrate Core Code to Submodules (tinyhumansai/openhuman, 42k stars) and Finishing A Development Branch (farm-fe/farm, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Suede CI Gate?

JasonColapietro (a GitHub user) maintains it in JasonColapietro/suede-creator-skills, which has 127 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 10, 2026.

Source: JasonColapietro/suede-creator-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.